← Back
CWE-1220

99 CVEs • Abstraction: Base

Insufficient Granularity of Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

JSON object

Loading...

CVEs (99)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Openstack Platform
Jun 17, 2026
Mar 15, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any con...Show more
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.Show less
1Microsoft
1Edge
Jun 17, 2026
Mar 14, 2024
N/A· v4
3.9 LOW· v3
N/A· v2
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
-
-
Jun 17, 2026
Mar 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be...Show more
The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on sites where user registration is supposed to be disabled.Show less
1Specklesystems
1Speckle Server
Jun 17, 2026
Dec 14, 2023
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which request...Show more
Speckle Server provides server, frontend, 3D viewer, and other JavaScript utilities for the Speckle 3D data platform. A vulnerability in versions prior to 2.17.6 affects users who: authorized an application which requested a 'token write' scope or, using frontend-2, created a Personal Access Token (PAT) with `token write` scope. When creating a new token an agent needs to authorise the request with an existing token (the 'requesting token'). The requesting token is required to have token write scope in order to generate new tokens. However, Speckle server was not verifying that other privileges granted to the new token were not in excess of the privileges of the requesting token. A malicious actor could use a token with only token write scope to subsequently generate further tokens with additional privileges. These privileges would only grant privileges up to the existing privileges of the user. This vulnerability cannot be used to escalate a user's privileges or grant privileges on behalf of other users. This has been patched as of version 2.17.6. All operators of Speckle servers should upgrade their server to version 2.17.6 or higher. Any users who authorized an application with 'token write' scope, or created a token in frontend-2 with `token write` scope should review existing tokens and permanently revoke any they do not recognize, revoke existing tokens and create new tokens, and review usage of their account for suspicious activity. No known workarounds for this issue exist.Show less
1Dell
5Apex Protection Storage
Emc Data Domain OsPowerprotect Data Domain+2 more
Jun 17, 2026
Dec 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulne...Show more
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an improper access control vulnerability. A local malicious user with low privileges could potentially exploit this vulnerability leading to escalation of privilege. Show less
1Redhat
1Openshift Logging
Jun 17, 2026
Aug 21, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authoriz...Show more
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.Show less
3Debian
PostgresqlRedhat
3Debian Linux
Enterprise LinuxPostgresql
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INS...Show more
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.Show less
1Microsoft
2.net
Visual Studio 2022
Jun 17, 2026
Jul 11, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
.NET and Visual Studio Elevation of Privilege Vulnerability
1Fossbilling
1Fossbilling
Jun 17, 2026
Jun 14, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
1Nvidia
1Connectx Firmware
Jun 17, 2026
Apr 22, 2023
N/A· v4
7.7 HIGH· v3
N/A· v2
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.
1Nvidia
1Connectx Firmware
Jun 17, 2026
Apr 22, 2023
N/A· v4
7.7 HIGH· v3
N/A· v2
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.
1Miniflux Project
1Miniflux
Jun 17, 2026
Mar 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `M...Show more
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publicly reachable Miniflux instance where the `METRICS_COLLECTOR` configuration option is enabled and `METRICS_ALLOWED_NETWORKS` is set to `127.0.0.1/8` (the default). A patch is available in Miniflux 2.0.43. As a workaround, set `METRICS_COLLECTOR` to `false` (default) or run Miniflux behind a trusted reverse-proxy.Show less
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
1Haascnc
1Haas Controller Firmware
Jun 17, 2026
Oct 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible ra...Show more
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources or resources out of context.Show less
2Gravitl
Netmaker
2Netmaker
Netmaker
Jun 17, 2026
Sep 9, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have...Show more
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, they can use their auth tokens to run admin-level functions via the API. This problem has been patched in v0.15.1.Show less
1Open Emr
1Openemr
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
1Open Emr
1Openemr
Jun 17, 2026
Mar 30, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
1Juniper
1Junos
Jun 17, 2026
Oct 19, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempt...Show more
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can successfully do so from any device interface regardless of the web-management configuration and filter rules which may otherwise protect access to J-Web. This issue affects: Juniper Networks Junos OS SRX Series 20.4 version 20.4R1 and later versions prior to 20.4R2-S1, 20.4R3; 21.1 versions prior to 21.1R1-S1, 21.1R2. This issue does not affect Juniper Networks Junos OS versions prior to 20.4R1.Show less